The recent cyber security incident affecting Beacon CRM has prompted many charities to consider an important question: what happens when a critical supplier suffers a cyber attack?
According to Beacon, unauthorised access to its systems resulted in copies of customer database backups being obtained by a third party, potentially affecting information held on behalf of more than 1,000 charities.
For many organisations, the incident is a reminder that a supplier's cyber attack can quickly become your organisation's problem. Indeed, many well-publicised data breaches over the past few years have ultimately arisen from a supplier or sub-contractor issue. Nonetheless, if personal data is compromised, the organisation using the platform is likely to remain responsible for assessing risks, considering notification requirements and protecting affected individuals.
The incident follows the publication of new National Cyber Security Centre (NCSC) guidance on recovering from a cyber attack. The guidance, published on 28 July 2026, is aimed at organisations of all sizes across the public and private sectors and focuses on the practical steps needed to recover from a serious cyber incident.
The NCSC's message is simple: recovery planning is just as important as prevention.
A three-stage approach
The guidance breaks recovery into three phases: immediate activities, recovery and investigation, and rebuild.
Stage 1: Immediate activities
The first few hours are often characterised by uncertainty, operational disruption and pressure to make quick decisions. The NCSC recommends establishing clear leadership, understanding the scope of the incident, engaging specialist support where required and identifying any urgent reporting obligations.
For organisations handling personal data, this will often include assessing whether a personal data breach has occurred and whether notification to the ICO or affected individuals is required.
Stage 2: Recovery and investigation
Once the situation has been stabilised, the focus shifts to restoring services, understanding what happened and engaging with key stakeholders. Organisations should allocate clear lines of responsibility, and maintain clear records of decisions and actions taken, as these may later be scrutinised by regulators, insurers or affected individuals.
Stage 3: Rebuild
Recovery should not simply be about returning to business as usual. The final stage is an opportunity to strengthen resilience by reviewing incident response plans, improving controls, testing business continuity arrangements and embedding lessons learned.
Key lessons from the Beacon incident
Organisations should consider whether they are prepared to:
- Respond quickly when a supplier reports a cyber incident.
- Assess data protection and regulatory obligations.
- Manage communications with customers, donors, staff and regulators.
- Coordinate legal, technical and operational responses.
- Maintain effective records throughout the incident.
How we can help
Cyber incidents require more than a technical response. They can raise complex regulatory, contractual, governance and reputational issues within hours. At Mills & Reeve, we support organisations throughout the lifecycle of a cyber incident, including:
- Assessing data breach notification obligations.
- Advising on communications with regulators and affected individuals.
- Managing supplier and contractual issues.
- Supporting investigations and incident response teams.
- Advising boards and senior leadership teams.
- Reviewing lessons learned and strengthening future resilience.
No organisation is immune from cyber risk. The organisations that recover most effectively are those that have planned ahead and know who to call when an incident occurs.
For more information, please get in touch with a member of our specialist cyber response team or read our Defensive lines report.
Our content explained
Every piece of content we create is correct on the date it’s published but please don’t rely on it as legal advice. If you’d like to speak to us about your own legal requirements, please contact one of our expert lawyers.